CVE-2018-1456
published 2018-06-06CVE-2018-1456: IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote…
PriorityP341high7.1CVSS 3.0
AVNACLPRLUINSUCHINAL
EPSS
2.02%
78.7th percentile
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20677 bootstrap: XSS in the affix configuration target property
bugzilla·2019-01-21·CVSS 6.1
CVE-2018-20677 [MEDIUM] CVE-2018-20677 bootstrap: XSS in the affix configuration target property
CVE-2018-20677 bootstrap: XSS in the affix configuration target property
A flaw was found in Bootstrap before 3.4.0. XSS is possible in the affix configuration target property.
References:
https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/
https://github.com/twbs/bootstrap/issues/27045
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628
Upstream Patch:
https://github.com/twbs/bootstrap/pull/27047
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3.2 zip
Via RHSA-2019:1456 https://access.redhat.com/errata/RHSA-2019:1456
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
bugzilla·2018-07-16·CVSS 6.1
CVE-2018-14041 [MEDIUM] CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the data-target property of scrollspy.
References:
https://github.com/twbs/bootstrap/issues/26627
Upstream Patch:
https://github.com/twbs/bootstrap/pull/26630
Discussion:
bootstrap 3.3.7 is not affected by this flaw.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3.2 zip
Via RHSA-2019:1456 https://access.redhat.com/errata/RHSA-2019:1456
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Via RHSA-2023:0553 https://access.redhat.com/errata/RHSA-2023:0553
---
This issue
2018-06-06
Published